Aaron Kaplan worked at cert.at for 12 years before reactivating his sole-proprietorship in 2020.
Since 2018 he has been fascinated by the possibilities, problems and pitfalls of AI for cybersecurity. He co-chairs the AI SIG at FIRST.org. Co-maintainer of IntelMQ.
- ai-connector: how to connect your local LLM to MISP - a new standard AI MISP module
.
- MAGIC Tricks for Microsoft 365 Incident Response: Hands-on AiTM Phishing and Business Email Compromise Investigations
Alex is a Security Consultant at DigiTrace GmbH.
Since 2022 he regularly conducts penetration tests with a focus on internal infrastructure and Active Directory, while finishing his studies in the IT Security field.
With a passion for open source he maintains several open source projects, including NetExec, wsuks and EVENmonitor.
- ESC17: Using ADCS to Attack HTTPS-Enabled WSUS Clients
Andras Iklody works at the Luxembourgian Computer Security Incident Response Team (CSIRT) CIRCL as a software engineer and has been leading the development of the MISP core since early 2013. These days he's found a new passion in agentic engineering and micro-managing his loyal army of AI agents. He is a firm believer that there are no problems that cannot be tackled by building the right tool.
- From Call for Failures to Slop Control: Agentic Engineering for Security Tooling
I spent my last decade at Google in the Android Security Team, to fight against Android malware !
I'm now working at CERT-EDF, to keep the light on ;)
- Analyzing Android Phones at Scale
As a seasoned dark web connoisseur and lead developer of the AIL project,
Aurélien enjoys exploring the complexities of the internet and analyzing it.
He is also a software engineer and analyst at CIRCL.
- HOPLITE: From Previously Unanalysed Data to Automated Intelligence
Bartek Górkiewicz is a Senior Application Security Engineer at Doyensec and a core maintainer of the InQL GraphQL security scanner. Previously, he worked as a Security Engineer at Idemia, where he gained experience testing systems related to payments and identity. Outside of his main role, he is an active bug bounty hunter who has discovered several vulnerabilities across enterprise platforms which were credited with CVEs. His background is primarily in web and mobile security, but he is actively expanding his research into IoT and embedded device security.
- Glucose in the Air: Wireless Medical IoT Without a Trust Anchor
Ben Folland is a volunteer researcher at Ctrl-Alt-Intel, where they investigate cybercrime and
espionage operations, track threat actor infrastructure, analyze TTPs, and expose threat actors.
His professional work has included stopping Akira affiliates, responding to Qilin, and Space Bear
ransomware incidents, investigating Storm-2603 activity linked to Warlock ransomware, tracking
Chinese adversaries targeting IIS servers for SEO fraud, and hunting DPRK malware used in
supply-chain attacks.
They are passionate about DFIR, threat hunting, CTI, malware analysis, and OSINT, and
regularly write about security research at Ctrl-Alt-Intel. They have previously spoken on the main
stage at DEF CON, as well as hack.lu, Malware Village, DC441905, and multiple BSides events.
- Bad Bears, Careless Kittens: State-Sponsored Espionage Exposed
- Turning the Tables: Command & no Control
Bernard is a community coordinator at the International Committee of the Red Cross (ICRC) Global Cyber Hub in Luxembourg. He draws on humanitarian-sector experience and a technical background to help connect humanitarian organizations with the open source community. He is an avid advocate of open source software and believes it is in humanity’s best interest when public-interest tools are developed in the open. He holds a Bachelor of Science in Computer Engineering and is interested in photography, music. His personal motto is “Evoliuvo: Evolve to help!”
- Soldering Workshop - Learn by doing
Coming from a software development background and having transitioned into the security domain, I really enjoy building prototypes, experimenting with new ideas, and exploring areas such as threat intelligence.
- A Generalized Fingerprinting Framework for Deriving Searchable Features to Identify Publicly Exposed Infrastructure
Bob is a senior (as in old and working for an eternity) CTI-Specialist of the NCSC-NL.
- A Generalized Fingerprinting Framework for Deriving Searchable Features to Identify Publicly Exposed Infrastructure
Chris Horsley is the CTO and co-founder at Cosive, a consultancy specialising in cyber threat intelligence and security operations. At Cosive, Chris leads the company's threat intelligence sharing and MISP initiatives and is a frequent speaker and trainer at industry conferences and meetups on these topics. Prior to co-founding Cosive, Chris spent many years in the international CSIRT community including working as an incident responder for both AusCERT and JPCERT/CC, the Japanese national CSIRT.
- Hostile Tools Aren't a Badge of Honour: UX for Security Engineers
In addition to providing his services as an independent cybersecurity expert, Christophe actively serves as a Belgian Cyber Reservist and contributes to open-source projects. He is the founder of the MISP Threat Sharing Platform and his contributions to the community also include the creation of MISP-maltego and pystemon, the active development of the sysdiagnose framework, as well as his previous involvement in organizing the FOSDEM conference.
When not immersed in the world of cybersecurity, Christophe enjoys outdoor pursuits such as hiking, climbing, mountaineering, and sailing, finding solace in the beauty of nature.
- iOS analysis using the Sysdiagnose analysis framework workshop - beginners session
- iOS analysis using the Sysdiagnose analysis framework workshop - advanced session
cybersecurity enthusiast, author, speaker and mathematician. Author of popular books:
MD MZ Malware Development Book (Github, 2022, 2024)
MALWILD: Malware in the Wild Book (Github, 2023)
Malware Development for Ethical Hackers Book: (Packt, 2024)
AIYA Mobile Malware Development Book (Github, 2025)
Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress)
Author and tech reviewer at Packt.
Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine
Malpedia contributor
Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Positive Hack Talks, etc conferences
- Signal processing and math for malware RnD for fun and profit
Security researcher at CIRCL since 2021. Core developer of Flowintel, Typosquatting-finder, Forensic Analyst, and other projects.
Passionate road cyclist in my free time.
- Flowintel v4.0 - MISP can you hear me ?
Csaba is an IT security practitioner with experience in penetration testing, malware analysis, computer forensics and incident response as well as CTI.
Csaba currently works at an international electronic entertainment provider as staff CTI analyst tracking threat actors. Previously worked in the automobile manufacturing industry in multiple roles (e.g.: SOC technical lead, IR, detection engineering and CTI) for multiple years and as IT security consultant before that.
- Tracking Information Leakers
Daniel Schwendner is a Cyber Security Specialist and former DevOps Engineer with a strong passion for Cyber Security. With a background in mobile application security and hardware security, he participates in bug bounty hunting and shares his security knowledge online.
- Poisoned at the Source: Hacking the Software Supply Chain in Your CI/CD Pipeline
Data Scientist who mainly works with Natural Language Processing.
Working on the Hoplite project.
- HOPLITE: From Previously Unanalysed Data to Automated Intelligence
Incident responder for more than a decade, I'm now working for the European Commission since 2015. I'm currently in charge of the "Situational Awareness, Threat Intelligence and Malware Analysis" in the European Commission Internal CERT (EC Cybersecurity Operation Centre).
- Coruna: a journey in a iOS analyst life studying the anatomy of an exploit kit
- iOS analysis using the Sysdiagnose analysis framework workshop - beginners session
- iOS analysis using the Sysdiagnose analysis framework workshop - advanced session
David Shandalov is a Staff Security Researcher at Palo Alto Networks, where he focuses on post-exploitation techniques, tracking the evolving malware threat landscape and Identity Security.
Previously, David worked as a Mobile Malware Researcher at Check Point and as a Security Researcher at Deep Instinct, gaining hands-on experience across multiple security doctrines and attack surfaces and presenting his findings at DEF CON. Outside of cybersecurity, he enjoys flying as a licensed private pilot.
- Cloak and Filter: Weaponizing the GPU and Windows Cloud Filter for File-less Execution and Privilege Escalation
David is a principal consultant at Alzette Information Security, an information security consulting company based in Europe. He has more than fifteen years of professional experience, two master's degrees, and he holds several IT security certifications. He is also a principal instructor at SANS Institute, teaching FOR572 and FOR509. David regularly speaks at international conferences, and he is a former member of the organizer team of the Security BSides Luxembourg conference.
- MAD data science for practical C2 detection - the workshop
Didier Stevens (SANS ISC Senior Handler) is a Senior Analyst working at NVISO. Didier has developed and published more than 100 open-source tools mostly for malware analysis, several of them popular in the security community. You can find his open source security tools on his IT security related blog https://blog.DidierStevens.com
- Practical Maldoc Analysis Workshop: The Unusual Suspects
- Ctrl Alt Compete
Matthias Kesenheimer is an experienced IT security professional with a passion for hardware hacking. As a senior IT security consultant and penetration tester for the German pentest company SySS GmbH, he specializes in the practical exploitation of vulnerabilities and advises clients on how to eliminate them. He also regularly conducts security research and has a keen interest in fault injection and voltage glitching attacks.
- Voltage Glitching Basics with the Pico Glitcher
Dries Depoorter is a Belgian artist and creative technologist who builds systems that exploit the gaps between surveillance infrastructure, AI, and public trust. His work turns openly available data streams, public cameras, social media APIs, parliamentary livestreams, into tools that expose how little privacy actually exists. His project "The Flemish Scrollers" uses real-time computer vision on government livestreams to detect and publicly tag politicians scrolling their phones during parliamentary sessions. "The Follower" combines open CCTV feeds with AI to match Instagram posts to the exact surveillance footage of the moment they were taken, proving how traceable our "curated" online lives really are. "Die With Me," a chat app that only works below 5% battery, became a viral experiment in digital scarcity and human behavior under constraint. With a background in electronics, computer vision, and hardware prototyping, Dries works across Arduino, Raspberry Pi, ESP32, and custom PCB design to build installations that function as both art and proof-of-concept exploits. He has exhibited at the Barbican, Art Basel, Ars Electronica, and ZKM, and has spoken at SXSW, MoMA, and TEDx.
- Surveilling Politicians, Unmasking Influencers, Fake Likes and Dying Together
Independent (security) researcher with a specific focus on wireless firmware reverse engineering, kernel programming and software obfuscation. Previously spoken/accepted at Nullcon Berlin 2025, Hardwear.io USA 2026, SEC-T Sweden 2026, BlackAlps 2026, Hack.lu 2026 and CONFidence conference 2026.
- LTECruiser: An Extremely low cost LTE Experimentation Framework
- When Victims Become Infrastructure: Inside Ink Dragon’s Victim-Based Relay Network
Eliad Kimhy is a Senior Security Researcher at Acronis, where he conducts research into emerging threats and cybercrime, and shares insights through conference talks and published reports. Eliad has worked with security teams for close to a decade, helping build and lead the development of threat intelligence production, and the publication of research-based content for technical and general audiences. He has spoken at conferences such as VirusBulletin, CARO, Insomnihack, Thotcon, BsidesSF, BsidesLV, and IT-SA. He is the co-creator and producer of the Webby Honoree podcast Malicious Life, which explores the untold stories and cultural history of hacking.
- From the Rebellious Cities: Anatomy of a State-Aligned Espionage Campaign
Eloïse Brocas is a security researcher and reverse engineer at Quarkslab She has a strong interest in creating tooling that support security analysts in their day-to-day tasks, some of these tools have been open-sourced like Pyrrha.
- Diving into Firmware Cartography with Pyrrha 2.0
Éric Leblond is the co-founder and chief technology officer (CTO) of Stamus Networks and a member of the board of directors at Open Network Security Foundation (OISF). Éric has more than 15 years of experience as co-founder and technologist of cybersecurity software companies and is an active member of the security and open-source communities.
He has worked on the development of Suricata – the open-source network threat detection engine – since 2009 and is emeritus member of the Netfilter Core team, responsible for the Linux kernel's firewall layer. Eric is also the lead developer of the Suricata Language Server, a real-time syntax checking and autocomplete app for Suricata rule writers.
Eric is a well-respected expert and speaker on network security.
- HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata
Eric Wagner is a post-doctoral researcher at the University of Luxembourg in the Security and Network Security (SNS) group headed by Prof. Dr. Vincent Lenders. Eric received a Ph.D. from RWTH Aachen University and worked as a researcher at Fraunhofer FKIE in the Cyber Analysis & Defense (CA&D) group before joining the University of Luxembourg. His research interest mainly focus on the security of communication protocols in cyber-physical systems.
- Automating the Reverse Engineering of CAN Bus Protocols with Physics-driven Traffic Analysis
Eva is a principal consultant at Alzette Information Security, an information security consulting company based in Europe. She has more than fifteen years of professional experience, two master's degrees in electrical engineering and in networks and telecommunication, and she holds several IT security certifications. Eva regularly speaks at international conferences, and she is a former member of the organizer team of the Security BSides Luxembourg conference.
- MAD data science for practical C2 detection - the workshop
- GoaTracer: A Hybrid Dynamic Analysis Platform
Ferdinand is a security researcher and penetration tester working at Fraunhofer Institute AISEC in Munich, Germany. His main focus lies with automotive security, but he takes a detour every now and then to explore other targets such as NFC and RF communication, exploit development or cracking crypto.
- The Good, the Bug and the Ugly - Dissecting a USB n-Day in the Linux Kernel
Félix is a Threat Intelligence specialist with 15 years of experience. Having previously worked at ANSSI and Kaspersky, he is now a Principal Threat Intelligence Researcher at Sekoia. His main areas of expertise include hunting for emerging threats, developing user-friendly software tools, and sharing his knowledge to enhance his team’s ability to discover, track, and analyze new cyber threats.
- Hunting requires a bit of luck
Long time member of syn2cat hackerspace. Sysadmin and security officer. Really good in linux, yoga, retrocomputing and massage.
- yoga for geeks
Hilko works in the CSIRT for a transportation and logistics company. He feels most comfortable when thinking about problems that touch systems programming, operations and IT security. For more than 25 years, he has learned to take free and open source software for granted and he is still amazed when he hears how others have found his contributions useful.
- Detecting Linux rootkits: Know where to look in user-space
Inbar has been teaching and lecturing about Internet Security and Reverse Engineering for nearly as long as he has been doing that himself. He started programming at the age of 9 and Reverse Engineering at the age of 14. He spent most of his career in the Internet and Data Security field, and the only reason he's not in jail right now is because he chose the right side of the law at an early age.
Inbar specializes in an outside-the-box approach to analyzing security and finding vulnerabilities, using his extensive experience of close to 30 years.
- Zero-Knowledge cracking of a 1983 Apple II Hardware Copy Protection
Israel Gubi is a Senior Security Researcher at Check Point Research, where he focuses on threat hunting and reverse engineering of advanced persistent threat (APT) groups. Israel’s research has been presented at leading security conferences including Virus Bulletin, BlueHat, and AVA
- When Victims Become Infrastructure: Inside Ink Dragon’s Victim-Based Relay Network
Jacob is the Head of Labs at Thinkst Applied Research. Prior to that he managed the HW/FW/VMM security team at AWS, and was a Program Manager at DARPA's Information Innovation Office (I2O). At DARPA he managed a cyber security R&D portfolio including the Configuration Security, Transparent Computing, and Cyber Fault-tolerant Attack Recovery programs. Jacob has been a speaker and keynote at conferences around the world, from BlackHat, to SysCan, to TROOPERS and many more.
- Bolting on security is the best we can [generally] do, so grab a wrench
Senior Cybersecurity Specialist at NASK’s Cybersecurity Team, focused on large-scale network event analysis and the day-to-day operation of a network telescope. Previously conducted IoT security research and developed a custom framework for penetration testing of Bluetooth devices. Holder of multiple cybersecurity certifications, including OSCP+.
- Internet Background Radiation: Exploiting the Void
Senior Software Engineer at NASK’s Cybersecurity Team, specializing in large-scale Internet measurements, darknet and network-telescope analytics, and vulnerability research. Author of multiple CVEs, including CVE-2023-4617 (CVSS 10.0), and contributor to projects focused on IoT security, Bluetooth threat analysis, and unsolicited-traffic intelligence. Speaker at the FIRST 26 Annual Conference and leading Polish cybersecurity events, including The Hack Summit and Oh My Hack. He holds an ICT background from Warsaw University of Technology.
- Internet Background Radiation: Exploiting the Void
I am a computer scientist with a background in software testing (automation), incident handling, threat intelligence sharing and security research.
- Project Rudzik - LLM assisted vulnerability hunting in open source projects
Jiří Vinopal is a security researcher, malware researcher, and reverse engineer at Check Point Research, focused on advanced cyber threats, kernel internals, and the hidden mechanics of undocumented system components. His work spans uncovering novel attack primitives, reconstructing proprietary protocols from binary analysis alone, and deep-diving into both sophisticated malware families and trusted platform components. When he's not buried in disassembly, he actively shares his knowledge and passion for reverse engineering across his X account, YouTube channel, and blog — delivering tips, tricks, and technical insights to fellow enthusiasts and the broader security community.
- BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive
Joining Shadowserver in 2016, Jon brings a range of skills and experience from UK Law Enforcement cyber crime investigation to the Foundation.
Engaging in consumer outreach, incident handling and the training of constituents in the use of Shadowserver public benefit services allows Jon the opportunity to deliver current threats and insights to all areas of the cyber community.
Of specific interest to Jon is international liaison and with the support of key public/private sector partners, the upskilling of developing cyber regions and National CERTs to ensure the effective use and understanding of Shadowserver’s bespoke datasets for a more secure internet.
- Global Telemetry to Local Remediation: Operationalizing Threat Intelligence for the Underserved
Jonathan spends a large proportion of his time breaking the things enterprises trust most but understand least. He specialises in IBM z/OS and IBM i security, not because it's fashionable, but because someone has to, and the systems running your bank's core transactions deserves more than a checkbox audit.
He analyses authorization models, maps privilege escalation paths, and explains to enterprises why their carefully designed access controls are actually a roadmap for attackers. At home he runs a lab that includes two AS/400s and enough enterprise equipment to make most corporate IT departments uncomfortable, because the best way to understand how to break something is to pwn one.
His current research applies modern offensive security methodology to platforms the industry forgot to threat-model, and demonstrates that the gap between a compromised AD account and privileged access on a mainframe may be smaller, and more traversable, than anyone in your SOC wants to hear.
- Six Degrees of RACF SPECIAL - Mainframe Attack Paths
Exploit Writer, Reverse Engineer, Pentester, Ethical Hacker, OSCP, OSCE, Linux Specialist (15+ years ), worked at Core Security, NOD32, Homeland Security (ArCERT), ING Nederland Red Team, KPN Red Team , RaboBank Red Team, Avast Red Team and others financial and security related organisations.
$whoami:
http://packetstormsecurity.com/search/?q=juan+sacco
https://www.exploit-db.com/?author=6701
Certifications:
- OSCP
- OSCE
- Advanced Corelan Exploit Development
- Advanced IDA Pro by HexRays
Conferences I participated worldwide as speaker:
NoHat - Windows Kernel Exploitation Training
BSides Frankfurt - Subverting the Windows kernel with rootkits and exploits
Black Hat Europe – Exploit Pack
HITB ( Hack in The Box ) - Exploit Writing 64 Bits
Black Hat – Exploit Pack tool
And more..
Publications and CVE’s:
NetPerf Hewllet Packard - Buffer Overflow ROP
Ivanti CVE2019-10885 – Privilege Escalation
Whatsapp 2.18.31 – Remote memory corruption
Kaspersky KSN – Remote RCE
BOCHS 2.6-5 Local Buffer Overflow
WhatsApp 2.17.52 Memory Corruption
Asterisk 13.17.2~dfsg-2 - CVE-2017-17090
MAWK 1.3.3-17 Buffer Overflow
PaloAlto Firewall PAN-57659/95895 - CVE-2016-2219
Microsoft Word MTA Handler Remote Code Execution
Facebook - Bug Bounty
Microsoft - Bug Bounty
Microsoft Windows Server 2008 R2 (x64) - SrvOs2FeaToNt' SMB - CVE-2017-0143
OSX – Xcode-select 2.1.1 Buffer Overflow
EChat Server 2.5 Buffer Overflow
Cisco ASA VPN Remote - CVE-2014-2120
xMatters AlarmPoint APClient 3.2.0 Heap Buffer Overflow
xMatters AlarmPoint Java Web Server API 3.2.1 SQLi
Easy Server 3.1 Buffer Overflow
Mercadolibre Persistent Web Vulnerability
BitchX 1.x IRC Client Buffer Overflow
Blender 2.0x Remote Code Execution
Microsoft Reporting tool Buffer Overflow
CDRipper 2.x Buffer Overflow
IRSSI Client 0.6x Remove Code Execution
VCDGEAR – Buffer overflow
MP3Info – Stack based buffer overflow
Perfectview CRM – Stored XSS and SQLi
Mobile IRON – XSS and SMTP Bypass
and more..
- Windows Kernel Exploitation
- Kernel Primitives to Code Execution on Windows 11 VBS/HVCI/kCET (SSDT/SSDT Shadow hooks)
Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, he is an expert in network flow analysis, reverse engineering, and social engineering. A lifelong command-line enthusiast, he uses bash daily for hacking, automation, and large-scale data processing.
He is the author of the jailbreak tool for MikroTik RouterOS and played a pivotal role in developing e-Saeima, the world's first fully remote legislative system used by the Latvian Parliament. Today, Kirils serves as lead researcher at Possible Security
- Mastering Bash for Hackers: Extreme Command-Line Power
Security Analyst at CERT.PL
- What's wrong with OT Security? Case study on how easily things break in Your hands when you try to squeeze them.
Coming from a bachelors in linguistics and driven by a long-standing enthusiasm technology and IT that started at kindergarden age, Laura Bernardy combined her passion for language and computer science through a Master’s degree in Computational Linguistics.
Her early research focused on NLP for Luxembourgish and other low-resource languages, where limited data availability and noisy texts pose significant technical challenges. Over time, this interest expanded towards another underexplored low-resource domain: dark web data. Similar to low-resource linguistic settings, underground data is highly noisy, fragmented, multilingual, and difficult to process – while additionally introducing challenges related to cybersecurity and threat intelligence.
Today, Laura is pursuing a PhD at the SnT Luxembourg, focusing on the intersection of NLP, dark web analysis, and CTI research. Her work explores how modern language technologies can be applied to extract actionable intelligence from unstructured underground data while remaining practical.
- From Text to Terrain: Automated Geolocation Analysis of Dark Web Data
Software engineer driven by a genuine passion for cybersecurity. Over the past four years, I contributed as a MISP core developer at the Computer Incident Response Center of Luxembourg CIRCL) and building tools such as network scanners and other projects that help CIRCL mission on keeping Luxembourg ecosystem safe.
- MISP Workbench: Hands-on threat intel platform workshop
Manuel is a security researcher driven by a passion to make threat actors’ lives harder. He works as a Cyber Security Analyst at dmTECH and also takes on freelance projects. When he’s off the clock, Manuel solves CTF challenges, writes blog posts for mboll.eu, and relaxes with a beer at the pub while philosophizing about the latest malware.
- The Bot Census: A Year Inside Malware's Telegram Ecosystem
- MAGIC Tricks for Microsoft 365 Incident Response: Hands-on AiTM Phishing and Business Email Compromise Investigations
Mathew Caplan has spent more than 25 years helping organisations improve cybersecurity and build resilience in an increasingly complex world.
As Director of Professional Services at Orange Cyberdefense, Mathew works with people across multiple industries and countries to address cyber risk and regulatory challenges.
Alongside his leadership role, he is a regular international conference speaker who believes cybersecurity should be accessible, engaging and people focused.
Through real-world insights, practical experience, storytelling and creativity, his talks explore how identity and human behaviour shape modern cybersecurity, making complex concepts understandable, memorable and actionable.
Whether advising executives, leading consulting teams or speaking on stage, his focus remains the same: helping organisations build trust, resilience and confidence amid constant change.
- Last night a DJ erased my drive - A musical journey through cybersecurity, chaos, and control
- SPOT - Spear-Phishing Overwatching Tool
Matteo Frigo received the B.E. degree from the University of Trento, Trento, Italy, in 2024. He is currently pursuing the M.E. degree in Cybersecurity Engineering at the Polytechnic University of Turin, Turin, Italy.
His main research interests include cybersecurity, automotive security, and machine learning.
- Automating the Reverse Engineering of CAN Bus Protocols with Physics-driven Traffic Analysis
Meera Tamboli is a DFIR Analyst with experience across SOC operations, incident response, and digital forensics within enterprise environments. Her work focuses on investigating real-world incidents, including phishing-driven attacks, credential compromise, and post-exploitation activity, with a strong emphasis on reconstructing attacker behaviour using endpoint, network, and identity telemetry.
She has spoken at cybersecurity conferences and events including BSides (London, Birmingham, Bristol), CSO Summit Manchester, WiCyS US, sharing insights on incident response, phishing techniques and practical DFIR investigations. Her sessions focus on translating real-world security incidents into clear, actionable lessons for both defensive and SOC teams.
She is passionate about making cybersecurity knowledge more accessible and practical. She actively contributes to the security community through content creation (YouTube 40K+ subscribers) and mentoring (500+ individuals mentored).
- The Human Side of Incident Response Failures: Why Mature SOCs Still Break Under Pressure
Since 2010, Michael Hamm has been working as an operator and analyst at CIRCL – Computer Incident Response Centre Luxembourg where he is working on forensic examinations and incident response.
- Bad out of Hell - FAT File System
Mohamed Ouad is a Senior Security Consultant focused on web apps and cloud infrastructure. Mohamed garnered his professional security experience at NTT Data Italy. There, he was involved in penetration testing and vulnerability assessments for critical insurance and telecommunications companies. During his research and bug bounty activities, Mohamed has been recognized by numerous companies including: Microsoft's MSRC, Kaspersky, the Dutch Cancer Society, Symantec, and ESET. He has also discovered multiple security vulnerabilities across various open-source projects, contributing responsible disclosures that helped strengthen their overall security posture.
- Glucose in the Air: Wireless Medical IoT Without a Trust Anchor
- The Good, the Bug and the Ugly - Dissecting a USB n-Day in the Linux Kernel
security researcher focused on the resilience of critical infrastructure
background in offensive security
- Satellites in the Sandbox: Hands-On Component Collusion and Aerospace C2 Evasion
- Satellites in the Sandbox: Hands-On Component Collusion and Aerospace C2 Evasion
Nicolas Diaz is a cyber security enthusiast. He studied linguistics until 1995 before becoming passionate about the internet. Nicolas turned to webmastering, completely self-taught. In 1999, within the International Federation for Human Rights (FIDH), he was trained by a French Navy system and network engineer. He then worked for the FIDH NGO for more than 15 years, training human rights defenders and journalists from around the world to improve the security of their communications.
Nicolas Diaz is a fervent promoter of open source and free software as an ally of human rights defenders. He was a Community Manager for YesWeHack from 2016 to 2019, and from 2020 to December 2022 was in charge of cyber projects for R&D company DIATEAM in Brest. Since 2023 he is the Chief Information Security Officer at Reporters Without Borders.
- Hunting requires a bit of luck
Nicolas Seriot is a security engineer. His earlier work focused on iPhone privacy, the Twitter API, and JSON parsing. He now writes about unusual corners of computing, most notably PostScript programming. His articles appear in Paged Out! magazine, his code lives at github.com/nst, and he is reliably drawn to making everyday tools do things their designers never intended.
- Unintended Computations
Niels Teusink is a Principal IT Security Expert at Eye Security, bringing over 20 years of hands‑on technical cybersecurity experience to the stage. His background spans red teaming, incident response, and SOC operations, and he previously spent years performing high‑impact penetration tests for governments, banks, and critical infrastructure. Though he now focuses on the blue side of cybersecurity, Niels remains passionate about offensive techniques and attacker tradecraft.
- Operation IXIM: Preventing a botnet of millions of PopCorn Time users
I'm Nándor Barta, a 17-year-old student from Germany. I've been into computers and coding since I was a kid. I started out with the Lego EV3, but instead of sticking to the standard block programming, I figured out how to run Python scripts using a micro-SD card in the programmable brick. After I graduate, I'm heading into Computer Science because I want to get into the IT field - specifically cybersecurity.
- Screen Time Sabotage: A Teenager’s Guide to Outsmarting Parental Controls
Olga Bogolyubova is an Assistant Professor at the Institute of Security and Global Affairs, Leiden University. Her research focuses on the intersection of trauma psychology, cyberpsychology, and digital harm, with particular interest in childhood adversity, online victimization, and harmful online behavior. She has published on topics including traumatic stress, cyber-aggression, online harm, and social aspects of digital risk. Dr. Bogolyubova previously held academic and research positions at the University of Malta, Clarkson University, Yale University, and St. Petersburg State University.
- Trauma-Informed Perspectives on Social Engineering: Beyond Cognitive Bias and Digital Literacy
Olivier Ferrand is a malware analyst and reverse engineer at the CERT of Crédit Agricole Group. He has been working in information security since the early 2000s. He is the creator and maintainer of RansomLook, an open-source platform tracking ransomware and data-extortion leak sites, and maintains several other trackers. He is a long-time contributor to CIRCL's open-source projects.
- From .onion to Structured Data: A Hands-On RansomLook Workshop
Paul Jung (paul.jung@circl.lu) is a long-time security professional with over two decades of experience in the cybersecurity field in Luxembourg. He has built extensive consulting expertise across multiple industries, covering activities from offensive security assessments to incident response and digital forensics. Prior to joining the Computer Incident Response Center Luxembourg (CIRCL), he served as Senior Security Architect in the Managed Network Security department of the European Commission, where he led the technical direction of major security projects. He later joined Excellium Services (acquired by Thales Group in 2022), where he founded and led TCS-CERT, a multi-country CSIRT dedicated to intrusion response. Paul regularly speaks at international conferences such as FIRST, Virus Bulletin, Botconf, and Hack.lu, and has published articles on DDoS, botnets, and incident response. He is a native French speaker and fluent in English.
- Internet Background Radiation: Exploiting the Void
Pauline Bourmeau is an independent security researcher specializing in the intersection of artificial intelligence, cognitive psychology, and threat intelligence. She has consulted on multilingual natural language processing, led deep learning and NLP workshops, and created training materials blending STEM with human factors. As founder of DEFCON Paris and contributor to the MISP project, she actively advances collaborative cybersecurity practices.
Previously, Pauline worked as a Threat Intelligence Analyst conducting OSINT, HUMINT, and SOCINT analysis to profile threats and investigate APTs. She holds a Master’s in Criminology with a thesis on cybersecurity intelligence sharing, and a background in sociolinguistics and computer science from Sorbonne and School 42.
- Applied Transformer NLP for Cybersecurity
- SPOT - Spear-Phishing Overwatching Tool
Paweł Pawliński is an expert at CERT.PL. His job experience includes data analysis, threat tracking, automation and coordinating international activities.
- Internet Background Radiation: Exploiting the Void
Pedro Umbelino holds the position of Principal Research Scientist at Bitsight and co-chairs the FIRST Time Security SIG.
His eclectic curiosity has led to the uncovering of vulnerabilities spanning a variety of technologies, highlighting critical issues in multiple devices and software, ranging from your everyday smartphone to household smart vacuums, from the intricacies of HTTP servers to the nuances of NFC radio frequencies, from vehicle GPS trackers to blowing up gas stations ATGs.
Pedro is committed to advancing cybersecurity knowledge and somehow help fixing Y2K38.
He has shared his findings at prominent conferences, including Bsides Lisbon, BruCON, Critical Effect, DEFCON, FIRST, Hack.lu, RSAC or Underground Economy.
- 1000 Ways to Die: The Convergence of IT/OT in Hospitals
Log time Cyber Threat Intelligence Analyst. Author of open source tools nfdump.
Passionate photographer.
- Flow Intelligence: Using NetFlow and nfdump for Network Visibility and Forensics
Member of the executive team at Open Network Security Foundation (OISF) and Suricata Project Evangelist. I have over 20 years of experience in the IT Security industry, including enterprise-level practice. Passionate user, developer, and explorer of innovative open-source security software. I have been involved with Suricata IDS/IPS/NSM from its very early days in 2009 as QA and training lead.
Co-founder and chief strategy officer (CSO) of Stamus Networks, a company providing commercial and open-source network detection and response solutions based on Suricata.
One of the lead maintainers of ClearNDR Community (former SELKS), the popular turnkey open-source based implementation of Suricata IDS/IPS/NSM.
Co-author of The Security Analyst’s Guide to Suricata book written with Eric
Leblond. SEPTun I and SEPTun II Suricata Extreme Performance Tuning series.
Peter is a writer, content creator and open source contributor about Network Cyber Security and authored over 150 blogs , 500 threat hunting visualizations and dashboards for Kibana/Elasticsearch and OpenSearch , written over 2000 detection rules, developed over 150 threat hunting trigger routines.
Authored scientific papers on Cyber Security Strategy and Defense.
Peter has developed and delivered over 100 hands on Cyber Security trainings and workshops for different government, public, private and defense organizations in US and Europe like the US Space command, US Missile command, NATO units.
10 years of hands on experience and instructor for NATO Counter Cyber Operations and Offensive Cyber Operations units in some of the largest live-fire cyber exercises such as Crossed Swords, Locked Shields.
Peter often engages in private or public training, workshops and speaking events in the area of cyber security and threat hunting at conferences such as DeepSec, FOSDEM, Troopers, BotConf, BSides, DefCon, Suricon, HackLu, SharkFest, RSA, Flocon, MIT Lincoln Lab and others.
- HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata
I am Pierre MARTY, a research engineer working for the LORIA in France.
My topics of interest are static and dynamic malware analysis, and cybersecurity in
general.
- GoaTracer: A Hybrid Dynamic Analysis Platform
Pierre-Marc Bureau is an independent security researcher. He has more than 20 years of experience in malware analysis, threat intelligence, reverse engineering, and the disruption of large-scale criminal operations. Over the last decade, he has held several roles at Google — first on Chrome, then on Safe Browsing, and most recently within the Threat Analysis Group (now part of Google's Threat Intelligence Group). Across the roles, he has focused on protecting billions of users from malware and phishing. He has also supported external partners and internal Google teams in combatting financially motivated threat actors.
Before joining Google, he worked at ESET and Dell SecureWorks. At both ESET and Google, he has built and led teams of analysts. He has presented at international conferences including Black Hat Europe, Recon, Hack.lu, and Virus Bulletin.
- My crimeware digital garden
Piotr Bienias is Adversary Researcher in Atos Threat Research Center with 5 years of experience in incident response, malware analysis, and threat hunting. He has led and supported complex investigations involving advanced threats, detection evasion, and large‑scale security incidents, combining deep hands‑on analysis with detection engineering and applied security research. His work regularly contributes to technical reports and conference‑grade publications focused on real‑world attacker tradecraft.
- Unmasking the Facade: Stealthy EtherRAT Distribution via Impersonated Administrative Tools on GitHub
Formerly member of CIRCL, I moved to France but didn't go that far in spirit as I'm still part of the developers and maintainers for a whole bunch of tools there. Some say it is too many, we disagree.
- Web forensics with Lookyloo and Lacus
With over 25+ years in the cybersecurity field, I have dedicated my career to safeguarding organisations by developing robust SOC and effective incident response teams. As a passionate advocate for knowledge sharing and collaboration - "sharing is caring"- I have actively contributed to the cybersecurity community and related open-source projects, such as MISP. In my current role, I have led the OpenTide initiative, turning it into a project at the core of the Detection Engineering team. I am looking for exchanging and collaborating with other Detection Engineering teams to develop repeatable, traceable, and pragmatic processes, effectively bridging the gap between Threat Intelligence, Threat Hunting, and Threat Detection.
- OpenTIDE Workshop – Build Your Own Operational DetectionOps Platform in 90 Minutes
Benoît is a cybersecurity analyst at EP-CERT, the European Parliament's computer emergency response team. He specialises in malware analysis, reverse engineering, and threat intelligence, with hands-on experience across the full defensive security stack. Curious by nature and craving for challenges, he is a regular CTF competitor ranking in the global top 100 of Flare-On for several consecutive years.
- Coruna: a journey in a iOS analyst life studying the anatomy of an exploit kit
- GoaTracer: A Hybrid Dynamic Analysis Platform
Rémi Matasse
I am Rémi Matasse (pseudo Remsio), a pentester that worked at Synacktiv for the past five years, passionated by offensive web security, especially on anything related to PHP.
I passed some years working on concrete PHP filters chain exploitation, documenting it in blogpost and presenting it in several conferences such as Pass The Salt, or hack.lu.
I then decided to focus on the Laravel since we often come across this framework during audits before jumped in with both feet on exploitation based on APP_KEY leaks and Laravel Livewire security mechanisms.
- CVE-2025-54068 : Deep dive into Livewire, from weak typing to pre-authenticated remote command execution
Security researcher at Quarkslab, focus on embedded targets and reverse engineering.
- Accelerate your reverse engineering process using SightHouse
Former Police Officer from Argentina, now a Cloud Incident Responder and Security Engineer with over 10 years of IT experience. A Digital Nomad an international speaker, I've presented on Cloud Security and Incident Response at Ekoparty, FIRST, Virus Bulletin (three times), Hack.Lu, and various BSides events worldwide. I hold a Bachelor's degree in Information Security and an MBA (Master in Business Administration).
- Polling is the Vulnerability: A Case for Event-Driven Cloud Detection
Saumil is an internationally recognised speaker and instructor, having regularly presented at conferences for 26 years. He has authored two books and a number of papers, a few of which made it to the prestigious PoC||GTFO.
Saumil graduated with an M.S. in Computer Science from Purdue University. He spends his leisure time breaking software, designing tabletop games, taking pictures and searching for tigers in the forests of India.
- SVGosploit - When Steganography Meets Vector Graphics
Sebastian Wagner is a Free Software enthusiast, full-stack software developer, and project manager.
He is located in Austria and currently works at Intevation, a small software firm in Germany.
With over ten years in IT security, including six years at CERT.at, he also co-maintains IntelMQ, a widely used CSIRT automation tool, for 12 years, and is a member of the Shadowserver Foundation and active and board member in two NGOs: The Institute for Common Good Technology and Engineers without Borderers Austria.
- Global Telemetry to Local Remediation: Operationalizing Threat Intelligence for the Underserved
Sébastien Bardin is a senior researcher at CEA LIST (Saclay, Paris area, France), where he has initiated and now leads the binary-level security analysis group. His research interests lay at the crossroad of formal methods and program analysis, security and software engineering. Especially, Sébastien is interested in automating binary-level code security analysis, with applications to vulnerability analysis, software-hardware attacks, reverse, deobfuscation and code protection. He is the main designer of the (open-source) BINSEC platform for binary-level code analysis. Sébastien regularly publishes articles in top-ranked international academic conferences and he occasionally gives talks at industrial venues such as Black Hat or the Meta TAV Symposium. Sébastien has co-chaired for many years the French national working group on Formal Methods & Security, and he co-leads SECUREVAL, a major initiative for security-oriented program analysis. Sébastien is a CEA Fellow.
https://scholar.google.com/citations?user=5tee-l8AAAAJ
https://binsec.github.io/
- Code-level security analysis: what about the attacker?
Trying to combine fun with some security related stuff
- Ctrl Alt Compete
Subhajeet Singha is a Senior Researcher at Acronis TRU Labs, working around threat intelligence, malware research, and reverse engineering. Subhajeet actively investigates advanced persistent threats (APTs), reverse-engineers complex malware strains, and contributes to research initiatives that improve threat detection & have previously presented research at Virus Bulletin, FIRST Conference, AVAR, ROOTCON.
- Khmer Shadow: Uncovering a Targeted Cyber Espionage Campaign Against Cambodian Military Intelligence
Sven Ulke is a Senior Manager in the Incident Response team of an owner-managed IT service provider. He has been working in IT since 2009, starting in system and network administration before moving into DFIR and Incident Response in 2015.
He holds a B.Eng. in Information Technology from DHBW and an M.Sc. in Digital Forensics from Albstadt-Sigmaringen University.
Sven has handled and led investigations and remediation efforts for large-scale security incidents, with a focus on APT cases in multinational environments, including DAX-40 companies. His work covers incident handling, forensic analysis, remediation strategy, and coordinating complex response projects.
Since 2023, he has been driving the development of Incident Response services in his current role, focusing on scalable analysis methods for major security incidents and building a DFIR partner network. He also shares practical knowledge through talks and community formats, and regularly contributes to open-source DFIR projects.
- MAGIC Tricks for Microsoft 365 Incident Response: Hands-on AiTM Phishing and Business Email Compromise Investigations
Sébastien Larinier began his career in SOC teams working on intrusion detection and founded the CERT Sekoia. Now a lecturer-researcher at ESIEA and an independent Cyber Threat Intelligence consultant, he contributes to several open-source projects such as MISP and Yeti. He is also the author of numerous articles, an international conference speaker, and teaches malware analysis, digital forensics, and Cyber Threat Intelligence at ESIEA while pursuing his PhD about the stalkerware at LORIA. He is co-author of Cybersécurité and Malware, published by Éditions ENI.
- Inside the Stalkerware Factory: Reversing C2 Protocols and Building Mock Servers for Three Commercial Stalkerware Families
Opensource developer at CIRCL
Working on integrations of Ghidra in the MISP ecosystem
- BSimVis: Scaling Binary Similarity and Clustering with Ghidra
Thomas Drake is a former senior executive with the National Security Agency (NSA), a decorated U.S. Air Force and Navy veteran, management and technology consultant, former Pro at Apple, and one of the most prominent whistleblowers in modern American history. During his tenure at NSA from 2001 to 2008, Drake exposed 9/11 intelligence failures and coverup, multi-billion dollar fraud, waste, and abuse in the agency's post-9/11 surveillance programs, including the illegal warrantless wiretapping program while advocating for technically robust and lawful constitutional alternatives that were summarily dismissed. He found himself charged under the Espionage Act in 2010, facing 35 years in prison but went free after the government’s criminal case against him collapsed.
Thomas Drake was also a computer software and systems engineering consultant and contractor specializing in code analysis, software-centric systems development and deployment, QA and testing, as well as serving as an intelligence analyst and signals intelligence specialist with over 25 years of technical and operational experience across the US intelligence system and as a management and technology consultant working with Silicon Valley companies during the go-go 90s and early 2000s.
His technical background includes in part the following:
Cryptology and Intelligence: Ten-year Air Force veteran specializing in intelligence operations, with extensive training in cryptology, electronic warfare, and signals analysis. Six years as an all-source intelligence officer in the Navy and a short stint at the CIA as an imagery analyst focused on weapons of mass destruction.
Large-Scale Data Mining Architecture: Developed a deep technical expertise in NSA data-analysis systems, including firsthand knowledge of data-mining platforms and breakthrough privacy-preserving encryption programs that also automated threat detection and profiling.
Intelligence Systems Architecture: 12 years as an NSA and defense contractor before joining NSA as a senior executive in 2001, with direct involvement in evaluating competing technical architectures and fielded systems.
Space and Cyberspace Operations: Expertise in intelligence, surveillance, and reconnaissance (ISR) systems and operations, and integration across air, space, and cyberspace domains.
Constitutionally-compliant Technical Design: Advocated for privacy-preserving technical implementations over constitutionally problematic mass-surveillance architectures, that made him one of the few senior NSA executives with both the technical depth and the documented willingness to prioritize constitutional safeguards over institutional momentum to collect it all. Served as an executive program manager for several breakthrough ‘skunks works’ projects meeting the core challenges of the Internet age with massive amounts of digital data.
Today, Drake is a leading advocate for government accountability, privacy rights, and whistleblower protections, speaking extensively on the dangers of unchecked surveillance states, autocratic power, the erosion of constitutional protections in the name of national security, and the moral imperative to resist institutional overreach and protect our precious human rights and liberties.
This combination of hands-on software and systems expertise, frontline operational intelligence and architecture experience, and demonstrated commitment to privacy-preserving systems in defense of humanity and keeping people out of harm’s way, continues to inspire him to speak out (and with alarm) on the intersection of cybersecurity, mass surveillance, and the defense of human agency in the AI age because it matters for who we are and our very future.
- The Panopticon Paradox: Cybersecurity in the Digital Age of AI-Accelerated Mass Surveillance
Thomas has 20 years experience in information security and has done lots of stuff in this area, from offensive to defensive security topics. Now he is doing incident response, threat hunting and threat intelligence at the Evonik Cyber Defense Team. Furthermore, he is co-founder of the Sigma project and maintains the open source toolchain (pySigma/Sigma CLI/Sigma MCP server).
- Detection Engineering with Sigma
Founder & CEO of Mint Secure GmbH: https://mint-secure.de/
Member of Chaos Computer Club and OWASP
Protecting what matters in a connected world
- When Responsible Disclosure Becomes a Criminal Investigation: Uncovering CVE-2025-43928 in Law Enforcement Surveillance Systems
Vincent is a Security Researcher at Synacktiv, where he performs vulnerability research and penetration testing across diverse environments. With over a decade of experience, he has conducted a wide range of security assessments, placing a primary focus on web application security. Vincent is dedicated to sharing his expertise and has led multiple training sessions, helping security professionals enhance their skills in this critical area.
X: @us3r777
LinkedIn: https://www.linkedin.com/in/vincent-herbulot/
- Enhanced Web Fuzzing - Improving your wordlists with tooling and methodology
William manages the technical team behind AS197692 at Conostix S.A. in Luxembourg. He’s been working in cybersecurity using free and opensource software on a daily basis for more than 25 years. Recently, he presented his work on SSL/TLS toolkits at Nullcon 2025 in Goa and Hack.lu 2025 in Luxembourg. He contributed to the cleanup and enhancement efforts done on SSLDump lately. He particularly enjoys tinkering with open (and not so open) hardware. Currently he likes playing around with new tools in the current ML scene, building, hopefully, useful systems for fun and, maybe, profit. When not behind an intelligent wannabe machine, he's doing analog music with his band of humans.
- In bed with Qubes OS, hands-on workshop
- SPOT - Spear-Phishing Overwatching Tool
Wojciech Bohatyrewicz is a Threat Researcher at Atos Threat Research Center with 13 years of experience in security operations across SOC and CSIRT. In his current role, he analyzes advanced threat activity, malware campaigns, and real‑world incidents, translating OSINT and telemetry into actionable intelligence for detection and response teams.
He has extensive experience as both a CSIRT Lead and long‑standing CSIRT Engineer, leading and supporting complex, high‑impact security incidents across enterprise environments. He also supported security operations during the Paris 2024 Olympic Games as a CSIRT Duty Manager.
He has handled major security incidents including enterprise‑wide compromises, ransomware, and advanced malware campaigns, with deep expertise in digital forensics and post‑compromise analysis.
- Unmasking the Facade: Stealthy EtherRAT Distribution via Impersonated Administrative Tools on GitHub
Xavier Mertens is a freelance security consultant running his own company based in Belgium (Xameco). With 15+ years of experience in information security, Xavier finds “blue team” activities more attractive. Therefore, his day job focuses on protecting his customers' assets by providing services like incident handling, malware analysis, forensic investigations, log management, security visualization, and OSINT). Besides his day job, Xavier is also a Senior Handler at the SANS Internet Storm Center, Principal SANS Instructor (FOR610, FOR710), security blogger and co-organizer of the BruCON security conference.
- C2 Evolution From the Past to Tomorrow